TanStack Supply Chain Attack Compromises 170 npm and PyPI Packages Including Major AI and Enterprise Tools
On May 11, according to
TeamPCP's shift to worm-driven propagation through CI/CD trust infrastructure represents a structural break from earlier supply chain campaigns, not an incremental escalation. The attack is the first documented instance of an npm worm producing validly attested SLSA Build Level 3 packages, directly invalidating provenance as a cleanliness signal for any organization that treats attestation as a security gate. Three successive monthly campaigns (Aqua Security's Trivy in March, Bitwarden CLI in April, and TanStack with Mistral AI in May) show an actor iterating rapidly on published research rather than developing novel techniques, compressing the lag between public vulnerability disclosure and weaponization. Mistral AI's confirmation that a developer device was involved validates the self-propagation logic beyond the initial TanStack's breach. With 400 attacker-controlled repositories already seeded with stolen credentials and the worm confirmed to have reached cloud, Kubernetes, and CI/CD environments, we assess it is likely within 30 days that TeamPCP will leverage harvested credentials to conduct secondary intrusions into downstream cloud or enterprise infrastructure. The dead man's switch, a shell script that executes rm -rf ~/ upon GitHub token revocation, marks a deliberate deterrence of incident response, complicating containment and raising the operational cost of remediation for any organization whose developers installed affected versions before deprecation.
4 sources
- Mistral AI SDK TanStack Router hit in npm software supply chain attack -
CSO Online - Postmortem: TanStack npm supply-chain compromise
- Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack -
Aikido Security - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages -
The Hacker News